Tag: detection
-
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up.AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI delivers…
-
Writing Suricata rules to detect commandcontrol traffic
Command-and-control traffic is one of the more useful places to apply network detection, because it often leaves repeatable patterns even when the payload is encrypted. Suricata is well suited to this work when you treat it as part of a wider detection stack rather than a single answer. For UK SMEs, the practical goal is……
-
Writing Suricata rules to detect commandcontrol traffic
Command-and-control traffic is one of the more useful places to apply network detection, because it often leaves repeatable patterns even when the payload is encrypted. Suricata is well suited to this work when you treat it as part of a wider detection stack rather than a single answer. For UK SMEs, the practical goal is……
-
Non-human identity (NHI) programs stall on detection, not policy
First seen on scworld.com Jump to article: www.scworld.com/perspective/non-human-identity-nhi-programs-stall-on-detection-not-policy
-
Cryptomining campaign avoids root access to evade detection
First seen on scworld.com Jump to article: www.scworld.com/brief/cryptomining-campaign-avoids-root-access-to-evade-detection
-
Okta übernimmt Permiso Security und erweitert seine Identity Threat Detection
Okta übernimmt Permiso Security und erweitert seine Plattform um Funktionen zur Erkennung und Abwehr von Identitätsbedrohungen in Cloud- und KI-Umgebungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/okta-uebernimmt-permiso-security-und-erweitert-seine-identity-threat-detection/a45972/
-
Okta Buys Permiso to Extend ITDR Beyond Native Identity Logs
Customers Gain Broader Identity Telemetry Across Cloud and Directory Services. Okta said its planned acquisition of Permiso will expand identity threat detection beyond native Okta telemetry by adding thousands of risk signals, AI agent security capabilities and graph-based correlation that combines identity exposures with active threats to improve detection and response. First seen on govinfosecurity.com…
-
Google AI Supercharges Chrome Security, Fixing 1,072 Bugs
Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…
-
Okta’s deal for Permiso aims to close gaps in identity threat detection
Ely Kahn, Okta’s chief product officer, told CyberScoop the deal enriches the company’s current threat detection tools and gives it deeper visibility into AI agent activity across enterprise systems. First seen on cyberscoop.com Jump to article: cyberscoop.com/okta-acquires-permiso-security-ai-identity-threat-detection/
-
Okta buys AI security startup Permiso, source says for about $200M
The deal gives Okta identity threat detection capabilities as enterprises seek to secure AI agents and other non-human identities across cloud environments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/30/okta-buys-ai-security-startup-permiso-source-says-for-about-200m/
-
Filtering Known-Bad Messages Does Not Prove Detection Readiness
Tags: detectionFirst seen on scworld.com Jump to article: www.scworld.com/risk-advisory/risk-advisory-filtering-known-bad-messages-does-not-prove-detection-readiness
-
The Case for Human Authority in AI-Driven Cybersecurity
AI Can Detect Threats Fast, but Only Humans Can Judge and Own the Response As AI takes on more of cybersecurity’s workload, from threat detection to automated response, the real question isn’t how much autonomy machines should have; it’s who remains accountable when they act. This piece makes the case for human authority over AI-driven…
-
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the…
-
Daylight Security Launches Detection Program Visibility
Daylight Security adds Detection Program Visibility to unify detections, map coverage to MITRE ATTCK, and help MDR customers spot gaps and improve results. First seen on hackread.com Jump to article: hackread.com/daylight-security-detection-program-visibility/
-
How to Build Application Detection and Response
Tags: detectionFirst seen on scworld.com Jump to article: www.scworld.com/implementation-guides/how-to-build-application-detection-and-response
-
Risk Advisory: Filtering Known-Bad Messages Does Not Prove Detection Readiness
First seen on scworld.com Jump to article: www.scworld.com/risk-advisory/risk-advisory-filtering-known-bad-messages-does-not-prove-detection-readiness
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea,…
-
Chaos ransomware deploys browser-based msaRAT to evade network detection
Cisco Talos uncovered msaRAT, a Chaos ransomware RAT that hides C2 traffic by routing it through Chrome or Edge using the Chrome DevTools Protocol. Cisco Talos disclosed msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that routes its entire command-and-control channel through the victim’s own Chrome or Edge browser. The malware…
-
Google Unveils CodeMender AI Agent for Automated Vulnerability Detection and Remediation
Google has unveiled CodeMender, a managed AI security agent designed to identify, validate, and remediate software vulnerabilities at machine speed. Announced in preview on July 22, 2023, the tool is available through the Gemini Enterprise Agent Platform and can also function as a core component of Google’s AI Threat Defense offering. This launch comes as…
-
New TrickBot Malware Variant Uses DNS Tunneling for CommandControl
A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a…
-
Why Modern SOCs Need Multi-Layered Detections
The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on First seen on thehackernews.com…
-
Sophisticated crypter service Cruciferra evades detection with advanced techniques
First seen on scworld.com Jump to article: www.scworld.com/brief/sophisticated-crypter-service-cruciferra-evades-detection-with-advanced-techniques
-
Cruciferra Crypter Evades Detection to Deliver Malware
Proofpoint found Cruciferra, a sophisticated crypter used to deliver malware through phishing campaigns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cruciferra-crypter-evades-detection-to-deliver-malware/
-
Cruciferra Crypter Evades Detection to Deliver Malware
Proofpoint found Cruciferra, a sophisticated crypter used to deliver malware through phishing campaigns. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/cruciferra-crypter-evades-detection-to-deliver-malware/
-
Fig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure
Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily. First seen on hackread.com Jump to article: hackread.com/fig-secops-engineering-lifecycle-security-teams-infrastructure/
-
Fig Expands SecOps Engineering Lifecycle as Security Teams Seek More Resilient Infrastructure
Learn how Fig adds testing, deployment, and continuous verification to SecOps, helping security teams keep detections reliable as infrastructure evolves. daily. First seen on hackread.com Jump to article: hackread.com/fig-secops-engineering-lifecycle-security-teams-infrastructure/
-
Hackers Abuse Ethereum Smart Contracts to Hide Amatera Stealer C2 Servers
Hackers are increasingly abusing decentralized infrastructure and legitimate development frameworks to evade detection, with a newly observed campaign leveraging Ethereum smart contracts to conceal command-and-control (C2) endpoints for the Amatera Stealer infostealer. These lures are propagated عبر malicious websites, file-sharing platforms such as Google Drive, MEGA, GoFile, and Wormhole, and spoofed download portals designed to…
-
Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries
Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == >>Public<< in the DeviceNetworkEvents table. As a result, traffic destined for public…
-
Hackers Use Cruciferra Crypter to Disable EDR and Deploy XWorm, Remcos, and AsyncRAT
Hackers are abusing the Cruciferra crypter-as-a-service to systematically turn off endpoint detection and response (EDR) tools and stealthily deploy XWorm, Remcos, AsyncRAT, and other commodity malware in email-driven campaigns targeting multiple sectors worldwide. By combining BYOVD-based driver abuse, indirect syscalls and a polymorphic encryption engine with more than 90 mix-and-match crypto routines, Cruciferra has rapidly…

